[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-security] SUN don't care about security update ?



Sun are only covering their butts here. Switch to another platform you'll be faced with same issues. The raq's are really as good their GUI, which is pretty good, saves heaps of time for webhosting.  If you want a server with your own flavor of unix to hack away at then you need to put in the time to config and admin the server with a security engineer to keep security in order. As the admin of the server you'll work yourself out if you try too take care of security and network administration. They are two entirely different fields.  With that said, you can't blame Sun for security issues, infact you can't blame anyone at all right now. Software is software, programs are buggy, always have been--they can never be pefect because we program them, and humans are not perfect. Applying the right patches when bugs found and keeping upto date is what security is all about. There is an update out for PHP on:

http://pkgmaster.com/packages/raq/4/#php

.mk


Thomas Mertz wrote:
The main issue is not Sun not supporting custom configs. That is their prerogative. The BIG issue is Sun not releasing security patches in a timely manner. For example Sun still has not released an official patch for the PHP vulnerability. Other vendors had patches out the same day. I think the complaint from people about custom configs is centered around the fact that in order to make the RAQ secure you have to install patches not provided by Sun. This is because the product is defective, not because they want to do something not supported on it. Since we are using other products as an example - This would be like Ford telling customers that they would have to wait months to get replacement tires for their defective Firestone ones, and that if you went to your own mechanic and installed safe tires your Ford warranty would be voided. For me, this issue makes the product unusable - I can't use a product that has major security flaws, nor am I willing to use an unsupported product. If Sun does not iron out it's security issues soon we will be switching all customers that are on Cobalt RAQs to another platform.
 
Tom